20.7 Dental Informatics, Electronic Records & Emerging Technology
Key Takeaways
- The HIPAA Privacy Rule governs use and disclosure of protected health information, while the Security Rule requires administrative, physical, and technical safeguards for electronic protected health information
- The minimum necessary standard limits use and disclosure to the least information needed, but it does not apply to disclosures for treatment purposes
- Patients have a right to access and obtain a copy of their record, generally within 30 days and for a reasonable cost-based fee
- A breach of unsecured protected health information requires notification to affected individuals and the Secretary of Health and Human Services, while encrypted data generally falls within safe harbor
- Teledentistry expands access for triage, consultation, and monitoring, but the standard of care, licensure requirements, and consent obligations are unchanged
Dental Informatics, Electronic Records & Emerging Technology
Why this matters on the INBDE: FK10 — research methodology, analysis, and informatics tools — carries 10% of examination items, and its largest cell is against Practice and Profession. Records and information technology are also two named Clinical Content areas.
The Electronic Dental Record
A complete record, electronic or paper, contains: patient identification and contact information; medical and dental history with dated updates; examination findings; radiographs and images; diagnoses; the treatment plan with alternatives presented; informed consent discussions; every treatment rendered with materials, anesthetic type and quantity, and lot numbers where required; prescriptions; laboratory prescriptions; referrals and consultation responses; missed and cancelled appointments; and all patient communications.
Advantages of electronic records: legibility, integrated imaging, automated recall and clinical alerts, e-prescribing with drug-interaction checking, structured data enabling practice-level quality measurement, and remote accessibility.
Risks specific to electronic records:
- Copy-forward error — carrying a prior note into today's entry so the record documents an examination that never happened.
- Template-driven entries that record findings not actually observed.
- Alert fatigue — clinicians dismiss warnings reflexively when too many fire.
- Audit trails — every view and edit is logged. This protects the patient and also means that late or altered entries are visible, so never attempt to alter an entry to conceal an event. Use the amendment function.
- Single point of failure — see the backup requirements in catastrophe preparedness.
HIPAA: Privacy, Security, and Breach Notification
The Privacy Rule
Governs the use and disclosure of protected health information (PHI) in any form.
| Concept | Rule |
|---|---|
| Permitted without authorization | Treatment, payment, and health care operations (TPO); disclosures required by law such as mandated abuse reporting, public health reporting, and certain law enforcement and judicial requests |
| Requires written authorization | Marketing, sale of PHI, most psychotherapy notes, and most other disclosures |
| Minimum necessary standard | Use and disclose the least information needed for the purpose — but this standard does not apply to disclosures for treatment |
| Notice of Privacy Practices | Must be provided and, at the first service encounter, a good-faith effort made to obtain acknowledgment of receipt |
| Patient rights | Access and a copy of the record (generally within 30 days, for a reasonable cost-based fee); request amendment; accounting of certain disclosures; request restrictions; request confidential communications; right to restrict disclosure to a health plan when the patient pays out of pocket in full |
| Business associate agreements | Required with vendors that create, receive, maintain, or transmit PHI on the practice's behalf — billing services, IT support, cloud storage, laboratories that receive PHI |
Incidental disclosures — a name overheard at the front desk — are permitted if reasonable safeguards are in place. The practical safeguards are quiet reception conversations, angled monitors and automatic screen locks, charts not left face-up, and a private area for financial and clinical discussions.
The Security Rule
Applies specifically to electronic PHI and requires three categories of safeguards:
- Administrative — a documented risk analysis, a risk management plan, assigned security responsibility, workforce training, sanction policy, and a contingency plan (data backup, disaster recovery, emergency mode operation).
- Physical — facility access controls, workstation security and positioning, and device and media controls including secure disposal and reuse.
- Technical — unique user identification, automatic logoff, access controls, audit controls, integrity controls, transmission security, and encryption.
Breach notification
A breach of unsecured PHI requires notification to affected individuals without unreasonable delay and no later than 60 days, to the Secretary of Health and Human Services (immediately for breaches affecting 500 or more individuals; annually for smaller breaches), and to prominent media for breaches affecting 500 or more residents of a state or jurisdiction.
Encryption is the practical safe harbor. A lost laptop or backup drive containing properly encrypted PHI generally does not constitute a breach of unsecured PHI; the same device unencrypted does, along with all the notification obligations that follow.
Ransomware involving PHI is presumed to be a breach unless a risk assessment demonstrates a low probability that PHI was compromised.
Teledentistry
Teledentistry is a delivery modality, not a different standard of care.
| Mode | Description | Typical dental use |
|---|---|---|
| Synchronous | Real-time audio-video | Consultation, triage, post-operative check |
| Asynchronous (store-and-forward) | Images and records transmitted for later review | Specialist review of radiographs and photographs |
| Remote patient monitoring | Data collected and transmitted over time | Orthodontic progress monitoring |
| Mobile health | Apps and messaging | Hygiene reinforcement, appointment adherence |
Obligations that do not change: the dentist must generally be licensed in the state where the patient is located; informed consent must include the limitations of a remote examination; documentation standards are identical; privacy and security requirements apply to the platform used; and prescribing rules, including controlled substance restrictions, still apply. Teledentistry expands access — especially for rural populations, long-term care residents, and school-based programs — but it cannot substitute for an examination when one is required to reach a diagnosis.
Digital Clinical Technology
| Technology | Value | Limitation to communicate |
|---|---|---|
| Digital radiography | Substantial dose reduction, instant image, enhancement and sharing | Image manipulation must preserve the original; do not enhance an image to create a finding |
| Cone beam CT | Undistorted three-dimensional anatomy | Higher dose; obligation to interpret the entire volume |
| Intraoral scanning | No impression material, immediate review, digital archiving | Learning curve; deep subgingival margins remain difficult to capture |
| CAD/CAM | Same-day restorations, consistent milling | Material limitations; occlusal design still requires clinical judgment |
| Caries detection devices (transillumination, fluorescence) | Adjunct sensitivity for occlusal lesions | False positives from stain and hypomineralization; never treat on a device reading alone |
| Electronic apex locators | Accurate working length with less radiation | Confirm with a radiograph in difficult anatomy |
| Artificial intelligence image analysis | Assists in caries and bone-level detection, workflow triage | Adjunct, not a diagnosis. The dentist remains responsible; training-data bias and false positives are real; regulatory clearance status matters |
Evaluating Emerging Technology
Before adopting anything new, ask:
- What clinical question does it answer better than the current method?
- What is the evidence? Peer-reviewed clinical outcome data, not a manufacturer's brochure or an opinion leader's lecture.
- Is it cleared or approved by the appropriate regulator for the use you intend?
- What is the learning curve, and what is the outcome during it?
- What are the failure modes, and can they be detected?
- What does it cost in equipment, materials, training, maintenance, and chair time — and does the benefit justify it for this patient population?
- What must the patient be told? Using a novel technique or material is a material fact in informed consent, and the patient is entitled to know that an established alternative exists.
The ethical anchor: enthusiasm for a new technology does not lower the evidentiary bar. A dentist who adopts an unproven technique and does not disclose its novel status has failed both the duty of competence and the duty of veracity.
A dentist refers a patient to an oral surgeon and sends the complete medical history and radiographs. Does the minimum necessary standard limit this disclosure?
An unencrypted practice laptop containing 800 patients' records is stolen. Which notification obligations apply?
An artificial intelligence tool flags a suspected interproximal lesion on a bitewing that the dentist does not identify clinically or radiographically. What is the appropriate response?
A dentist licensed in State A wishes to provide a synchronous teledentistry consultation to a patient physically located in State B. What is the primary licensure consideration?